VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (10,097)

page 488 of 505
  • CVE-2026-55052HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-58279MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.01

    Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-60119MedJul 14, 2026
    risk 0.00cvss 5.4epss 0.00

    Hi.Events before 1.11.0 contains a cross-site scripting vulnerability that allows authenticated attackers with event creation or edit permissions to inject arbitrary HTML and JavaScript by embedding a malicious event title containing the sequence, which is not escaped…

  • CVE-2026-60118MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.00

    Hi.Events before 1.11.0 contains a missing server-side visibility enforcement vulnerability that allows unauthenticated attackers to purchase hidden tickets by referencing hidden product and price IDs in order creation requests without authorization checks. Attackers can…

  • CVE-2026-12988MedJul 14, 2026
    risk 0.00cvss 6.4epss 0.00

    The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the user, allowing an attacker who has obtained a user's credentials to redirect the setup verification code to an attacker-controlled…

  • CVE-2026-11802MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.01

    The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5.6. The registration() function, accessible via the wp_ajax_nopriv_registration_action AJAX action, lacks any nonce verification…

  • CVE-2026-44771MedJul 14, 2026
    risk 0.00cvss 4.3epss 0.00

    SAP S/4HANA Draft operation does not perform necessary authorization checks for an authenticated user, a restricted user could access information within the entity resulting in escalation of privileges. This results in low impact on confidentiality, with no impact on integrity…

  • CVE-2026-44770MedJul 14, 2026
    risk 0.00cvss 4.3epss 0.00

    SAP Create Single Payment does not perform necessary authorization checks for an authenticated user, a restricted user could access specific entity set keys resulting in disclosure of information. This has low impact on confidentiality, with no impact on integrity and…

  • CVE-2026-62328HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.01

    9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user data by sending requests to unprotected API endpoints. Attackers can enumerate paginated request logs and retrieve complete AI…

  • CVE-2026-62194HigJul 13, 2026
    risk 0.00cvss 8.8epss 0.00

    OpenClaw versions 2026.5.20 before 2026.6.9 contain a privilege escalation vulnerability in plugin install commands that allows lower-trust callers to execute or persist actions beyond their intended authorization. Attackers can exploit misconfigured input paths or enabled…

  • CVE-2026-62191HigJul 13, 2026
    risk 0.00cvss 7.1epss 0.00

    OpenClaw versions 2026.6.6 before 2026.6.9 contain an authorization bypass vulnerability in message mutation handling that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to skip requester…

  • CVE-2026-62186HigJul 13, 2026
    risk 0.00cvss 7.6epss 0.00

    OpenClaw versions before 2026.6.8 contain an authorization bypass vulnerability in OpenAI-compatible HTTP model overrides that allows lower-trust callers to perform actions requiring stronger authorization checks. Attackers can exploit misconfigured input paths to bypass admin…

  • CVE-2026-58410HigJul 13, 2026
    risk 0.00cvss 7.1epss 0.00

    ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the family-scoped endpoints which allowed low-privileged users to read and modify other families’ records. An authenticated non-admin user with EditSelf access can…

  • CVE-2026-58408MedJul 13, 2026
    risk 0.00cvss 6.5epss 0.00

    ChurchCRM is an open-source church management system. Prior to version 7.4.0, a low-privileged user can bypass the /admin/export UI and exfiltrate the entire member directory. The POST /CSVCreateFile.php endpoint generates and streams a CSV containing the full Personally…

  • CVE-2026-9824MedJul 13, 2026
    risk 0.00cvss 4.3epss 0.00

    Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, which allows an authenticated user without that permission to enumerate configured remote cluster…

  • CVE-2026-9820LowJul 13, 2026
    risk 0.00cvss 3.8epss 0.00

    Mattermost versions 11.7.x <= 11.7.2, 10.11.x <= 10.11.19 fail to sanitize team objects returned by the scheme teams endpoint, which allows a user with the User Manager role to obtain invite links for private teams and use them to join or share access to those teams via the…

  • CVE-2026-14934CriJul 13, 2026
    risk 0.00cvss —epss 0.00

    A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versions between October 2025 and May 10th, 2026, on Google Cloud Platform, allows an authenticated attacker to escalate privileges and…

  • CVE-2026-61985MedJul 13, 2026
    risk 0.00cvss 5.3epss 0.00

    Missing Authorization vulnerability in magepeopleteam Car Rental Manager car-rental-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Car Rental Manager: from n/a through <= 1.3.7.

  • CVE-2026-61983MedJul 13, 2026
    risk 0.00cvss 5.3epss 0.00

    Missing Authorization vulnerability in andy_moyle Church Admin church-admin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Church Admin: from n/a through <= 5.0.30.

  • CVE-2026-61968MedJul 13, 2026
    risk 0.00cvss 5.4epss 0.00

    Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 3.1.2.